ChainBleedv0.1 · open intel
← back to feed·INFRASTRUCTURE2026-04-18 · 1mo ago
Incident · SLOWMIST

Kelp DAO

Infrastructure-level attack
Estimated loss
$293.00M
VERDICT —OUT OF SCOPE
Root cause is infrastructure (DNS / cloud / database / third-party API) compromise, not on-chain contract logic. Pre-deployment source review would not surface this; coverage lives in cloud-security + supply-chain audit, separate discipline.
▰ METHOD
INFRASTRUCTURE
INFRASTRUCTURE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

LayerZero issued a statement saying that on April 18, Kelp DAO suffered an attack resulting in approximately $290 million in losses. The incident is initially assessed to have been carried out by a highly sophisticated nation-state actor, suspected to be the TraderTraitor subgroup of North Korea’s Lazarus Group. The attack was completely isolated to Kelp DAO’s rsETH configuration and was caused by its use of a single DVN (Decentralized Verifier Network) setup. The LayerZero protocol itself was not exploited, and no other cross-chain assets or applications were affected. The core of the attack involved the hacker compromising downstream RPC infrastructure used by LayerZero’s DVN. The attacker obtained the RPC node list used by the DVN, then infiltrated two independent RPC nodes. They replaced the op-geth binary and used a custom payload to forge messages. This setup allowed the attacker to display false data only to the DVN, while showing correct data to other observers, including LayerZero Scan. The attacker then launched a DDoS attack against the uncompromised RPC nodes, forcing a failover to the poisoned RPC nodes. As a result, the DVN accepted the falsified messages, enabling the attack to succeed. After the attack was completed, the attacker removed the malicious binaries, logs, and configuration files. LayerZero has since decommissioned all affected RPC nodes, replaced them, and confirmed that the DVN has returned to normal operation. Attack method (per SlowMist): Infrastructure-level attack. Reported loss: $ 293,000,000.

Primary source
https://x.com/LayerZero_Core/status/2046081551574983137
Sourced from
slowmist
Technical record
chain
protocol
Kelp DAO
bug_class
infrastructure
date_occurred
2026-04-18
loss_usd
$293,000,000
source_id
sm:kelp-dao::2026-04-18
Related — same bug class· infrastructure
2026-04-18
1mo ago
DNS registrar for eth.limo
DNS hijacking
infrastructure
OUT OF SCOPE
2026-04-04
2mo ago
HypurrFi
Domain Hijacking
infrastructure
OUT OF SCOPE
2026-03-31
2mo ago
Steakhouse Financial
Social Engineering
infrastructure
OUT OF SCOPE
2026-03-19
2mo ago
Neutrl
DNS Hijacking
infrastructure
OUT OF SCOPE
2026-03-18
2mo ago
ETH
Neutrl
DNS Hijacking Attack
infrastructure
OUT OF SCOPE
2026-03-11
3mo ago
BONKfun
Social Engineering Attack➕Domain Hijacking➕Phishing
infrastructure
$30.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence